Natural-Language Policy Violations
Medium
- Confidence
- 90% confidence
- Finding
- The documentation states that OAuth device authorization grants read, publish, engage, and manage access in one login and that users do not choose scopes. This violates least-privilege principles by normalizing broad account access even for read-only use, increasing the blast radius if tokens are stolen, misused by an agent, or used for unintended write operations.
